# AdwCleaner v4.101 - Report created 16/11/2014 at 16:14:05 # Updated 09/11/2014 by Xplode # Database : 2014-11-16.1 [Live] # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : Billy - BILLY-HP # Running from : C:\Users\Billy\Desktop\Malware-Fixes\AdwCleaner.exe # Option : Scan ***** [ Services ] ***** Service Found : APNMCP Service Found : UtilityChest_49Service ***** [ Files / Folders ] ***** File Found : C:\Users\Alyana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage File Found : C:\Users\Alyana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal File Found : C:\Users\Alyana\AppData\LocalLow\SkwConfig.bin File Found : C:\Users\Alyana\AppData\Roaming\Mozilla\Firefox\Profiles\jyvn16ad.default\searchplugins\ask-search.xml File Found : C:\Users\Alyana\AppData\Roaming\Mozilla\Firefox\Profiles\jyvn16ad.default\searchplugins\MyStart Search.xml File Found : C:\Users\Billy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_app.mam.conduit.com_0.localstorage File Found : C:\Users\Billy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_app.mam.conduit.com_0.localstorage-journal File Found : C:\Users\Billy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage File Found : C:\Users\Billy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal File Found : C:\Users\Billy\AppData\LocalLow\SkwConfig.bin File Found : C:\Users\Billy\AppData\Roaming\Mozilla\Firefox\Profiles\k4ecvf1n.default\Extensions\addon@defaulttab.com.xpi File Found : C:\Users\Billy\AppData\Roaming\Mozilla\Firefox\Profiles\k4ecvf1n.default\searchplugins\Askcom.xml File Found : C:\Users\Billy\AppData\Roaming\Mozilla\Firefox\Profiles\k4ecvf1n.default\searchplugins\ask-search.xml File Found : C:\Users\Billy\AppData\Roaming\Mozilla\Firefox\Profiles\k4ecvf1n.default\searchplugins\safeguard-secure-search.xml File Found : C:\Users\Billy\AppData\Roaming\Mozilla\Firefox\Profiles\k4ecvf1n.default\searchplugins\search-here.xml File Found : C:\Users\Billy\AppData\Roaming\Mozilla\Firefox\Profiles\k4ecvf1n.default\searchplugins\Sweetpacks Search.xml File Found : C:\Users\Billy\AppData\Roaming\Mozilla\Firefox\Profiles\k4ecvf1n.default\user.js File Found : C:\Users\Kaliyah\AppData\Roaming\Mozilla\Firefox\Profiles\fd33t34s.default\searchplugins\ask-search.xml File Found : C:\Users\Nyjah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage File Found : C:\Users\Nyjah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal File Found : C:\Users\Nyjah\AppData\Roaming\Mozilla\Firefox\Profiles\ao6m9a7j.default\searchplugins\ask-search.xml File Found : C:\Windows\System32\drivers\rsdrvx64.sys Folder Found : C:\Program Files (x86)\Ask.com Folder Found : C:\Program Files (x86)\AskPartnerNetwork Folder Found : C:\Program Files (x86)\AVG SafeGuard toolbar Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search Folder Found : C:\Program Files (x86)\Conduit Folder Found : C:\Program Files (x86)\Deals Plugin Folder Found : C:\Program Files (x86)\defaulttab Folder Found : C:\Program Files (x86)\LemurLeap Folder Found : C:\Program Files (x86)\otshot Folder Found : C:\Program Files (x86)\UtilityChest_49 Folder Found : C:\Program Files (x86)\Whilokii Folder Found : C:\ProgramData\apn Folder Found : C:\ProgramData\Ask Folder Found : C:\ProgramData\AskPartnerNetwork Folder Found : C:\ProgramData\Conduit Folder Found : C:\ProgramData\NCH Software Folder Found : C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\37aks078.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} Folder Found : C:\Users\Alyana\AppData\Local\AskPartnerNetwork Folder Found : C:\Users\Alyana\AppData\Local\Temp\apn Folder Found : C:\Users\Alyana\AppData\LocalLow\AskToolbar Folder Found : C:\Users\Alyana\AppData\LocalLow\UtilityChest_49 Folder Found : C:\Users\Alyana\AppData\Roaming\Mozilla\Firefox\Profiles\jyvn16ad.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} Folder Found : C:\Users\Alyana\AppData\Roaming\NCH Software Folder Found : C:\Users\Alyana\AppData\Roaming\SearchProtect Folder Found : C:\Users\Billy\AppData\Local\AskPartnerNetwork Folder Found : C:\Users\Billy\AppData\Local\Conduit Folder Found : C:\Users\Billy\AppData\Local\SwvUpdater Folder Found : C:\Users\Billy\AppData\Local\Temp\apn Folder Found : C:\Users\Billy\AppData\Local\UtilityChest_49 Folder Found : C:\Users\Billy\AppData\LocalLow\AskToolbar Folder Found : C:\Users\Billy\AppData\LocalLow\Conduit Folder Found : C:\Users\Billy\AppData\LocalLow\iac Folder Found : C:\Users\Billy\AppData\LocalLow\PriceGong Folder Found : C:\Users\Billy\AppData\LocalLow\UtilityChest_49 Folder Found : C:\Users\Billy\AppData\Roaming\defaulttab Folder Found : C:\Users\Billy\AppData\Roaming\Mozilla\Firefox\Profiles\k4ecvf1n.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} Folder Found : C:\Users\Billy\AppData\Roaming\Mozilla\Firefox\Profiles\k4ecvf1n.default\Extensions\addon@defaulttab.com.xpi Folder Found : C:\Users\Billy\AppData\Roaming\Mozilla\Firefox\Profiles\k4ecvf1n.default\Extensions\firefox@lemurleap.info.xpi Folder Found : C:\Users\Billy\AppData\Roaming\SearchProtect Folder Found : C:\Users\Billy\Documents\Optimizer Pro Folder Found : C:\Users\Kaliyah\AppData\Local\AskPartnerNetwork Folder Found : C:\Users\Kaliyah\AppData\Local\Temp\apn Folder Found : C:\Users\Kaliyah\AppData\LocalLow\AskToolbar Folder Found : C:\Users\Kaliyah\AppData\LocalLow\UtilityChest_49 Folder Found : C:\Users\Kaliyah\AppData\Roaming\Mozilla\Firefox\Profiles\fd33t34s.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} Folder Found : C:\Users\Kaliyah\AppData\Roaming\SearchProtect Folder Found : C:\Users\Nyjah\AppData\Local\AskPartnerNetwork Folder Found : C:\Users\Nyjah\AppData\Local\Temp\apn Folder Found : C:\Users\Nyjah\AppData\LocalLow\AskToolbar Folder Found : C:\Users\Nyjah\AppData\LocalLow\UtilityChest_49 Folder Found : C:\Users\Nyjah\AppData\Roaming\Mozilla\Firefox\Profiles\ao6m9a7j.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} Folder Found : C:\Users\Nyjah\AppData\Roaming\SearchProtect Folder Found : C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe} ***** [ Scheduled Tasks ] ***** Task Found : Scheduled Update for Ask Toolbar ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCU\Software\APN Key Found : HKCU\Software\AppDataLow\Software\AskToolbar Key Found : HKCU\Software\AppDataLow\Software\Crossrider Key Found : HKCU\Software\AppDataLow\Software\Deals Plugin Key Found : HKCU\Software\AppDataLow\Software\Smartbar Key Found : HKCU\Software\AppDataLow\Software\SmartBar Key Found : HKCU\Software\AppDataLow\Software\UtilityChest_49 Key Found : HKCU\Software\Ask.com Key Found : HKCU\Software\AskPartnerNetwork Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\Default Tab Key Found : HKCU\Software\InstallCore Key Found : HKCU\Software\InstalledBrowserExtensions Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0C434ECE-1520-4120-8170-39B3E7D3843A} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{a776248f-c424-4ce4-8b5e-65db029465d3} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CF67755F-9265-449C-87CF-B945519E073B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF67755F-9265-449C-87CF-B945519E073B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\FLV Player Key Found : HKCU\Software\pc optimizer pro Key Found : HKCU\Software\UtilityChest_49 Key Found : [x64] HKCU\Software\APN Key Found : [x64] HKCU\Software\Ask.com Key Found : [x64] HKCU\Software\AskPartnerNetwork Key Found : [x64] HKCU\Software\Conduit Key Found : [x64] HKCU\Software\Default Tab Key Found : [x64] HKCU\Software\InstallCore Key Found : [x64] HKCU\Software\InstalledBrowserExtensions Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0C434ECE-1520-4120-8170-39B3E7D3843A} Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4B5C-9287-DA72D38F4FE6} Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6} Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{a776248f-c424-4ce4-8b5e-65db029465d3} Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3} Key Found : [x64] HKCU\Software\pc optimizer pro Key Found : [x64] HKCU\Software\UtilityChest_49 Key Found : HKLM\SOFTWARE\APN Key Found : HKLM\SOFTWARE\AskPartnerNetwork Key Found : HKLM\SOFTWARE\AskToolbar Key Found : HKLM\SOFTWARE\Classes\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007} Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Found : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Found : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D} Key Found : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D} Key Found : HKLM\SOFTWARE\Classes\CLSID\{13119113-0854-469D-807A-171568457991} Key Found : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472} Key Found : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472} Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{23699B0B-C14D-4054-A545-FC0927BB0879} Key Found : HKLM\SOFTWARE\Classes\CLSID\{25151605-D156-49DD-A659-20E69C1EE15F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{268CA04C-106C-4636-B707-95E8CD5859E0} Key Found : HKLM\SOFTWARE\Classes\CLSID\{2BB3E614-F616-42DD-A99A-69C1FC268741} Key Found : HKLM\SOFTWARE\Classes\CLSID\{33119133-0854-469D-807A-171568457991} Key Found : HKLM\SOFTWARE\Classes\CLSID\{35274ADF-B8DE-4909-80D1-A26269216903} Key Found : HKLM\SOFTWARE\Classes\CLSID\{3F2F1B3C-EDA7-46EC-A1CA-12A67CD00A82} Key Found : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664} Key Found : HKLM\SOFTWARE\Classes\CLSID\{5BBF357E-EA8C-48BF-83CA-DE279FB83BBA} Key Found : HKLM\SOFTWARE\Classes\CLSID\{6AAFD84D-5F7F-42E5-9FB4-157925C3ED2F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{878A5A0A-DC0A-4C37-BBE2-18C30E50F449} Key Found : HKLM\SOFTWARE\Classes\CLSID\{8C428C4B-C9E2-4B74-B791-88C3FEE48F36} Key Found : HKLM\SOFTWARE\Classes\CLSID\{929825DF-A1B4-40C9-8F3C-6DA06BADC150} Key Found : HKLM\SOFTWARE\Classes\CLSID\{9F19923D-2A4C-45EF-A026-AE7DEE5D022C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A72B8EA8-5B63-4C90-9FE8-D9C76C99DE32} Key Found : HKLM\SOFTWARE\Classes\CLSID\{C86BFADB-406F-47C7-A8D8-FAA37B39089F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CF67755F-9265-449C-87CF-B945519E073B} Key Found : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{D92EDE9A-70A4-469F-AF8F-38C3F278B0A1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F67A3AA8-88EE-4A3A-863A-B13A19F8696C} Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Found : HKLM\SOFTWARE\Classes\Installer\Features\90C64EA18BA25EE488BF80DCF07F2FFD Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Classes\Installer\Products\90C64EA18BA25EE488BF80DCF07F2FFD Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLM\SOFTWARE\Classes\Interface\{13B8FF9D-DEB0-4070-B846-D049218307B3} Key Found : HKLM\SOFTWARE\Classes\Interface\{1E877590-30B7-400E-A835-B942489EB7BC} Key Found : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991} Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Found : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1} Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{103E3C9A-E8AE-4B19-A339-01FE9439763E} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{326C4F48-FE3B-4E54-9118-9B6C3B6C9B1E} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{39D884BB-2881-4F3A-B9B9-2D3AF4C2C191} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{59E5BDB9-126F-4575-901E-D32132A19B94} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{5CF866F0-10A3-4ED4-9BE3-668F2F148E2F} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{618B2F0C-A1AF-4D1D-9354-CF0C42AF5BCB} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8EFEE482-37BC-4F3D-83E6-CB5BBE077E43} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{CE1482C8-E8FD-4277-9A4F-094D712F6B60} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EEA63863-87BC-4DCA-A5B5-EB97E3B04806} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EEFDBFA7-0F18-4216-8F90-6B6F71D6AB83} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{F12BA68C-976E-4567-BA3B-629DFCEBC5FE} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{F66F6A81-E727-4774-B461-8A5CB7F7DE07} Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.FeedManager Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.FeedManager.1 Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.HTMLMenu Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.HTMLMenu.1 Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.HTMLPanel Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.HTMLPanel.1 Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.MultipleButton Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.MultipleButton.1 Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.PseudoTransparentPlugin Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.PseudoTransparentPlugin.1 Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.Radio Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.Radio.1 Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.RadioSettings Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.RadioSettings.1 Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.ScriptButton Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.ScriptButton.1 Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.SettingsPlugin Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.SettingsPlugin.1 Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.ThirdPartyInstaller Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.ThirdPartyInstaller.1 Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.ToolbarProtector Key Found : HKLM\SOFTWARE\Classes\UtilityChest_49.ToolbarProtector.1 Key Found : HKLM\SOFTWARE\firstsearch Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl Key Found : HKLM\SOFTWARE\InstallIQ Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{878A5A0A-DC0A-4C37-BBE2-18C30E50F449} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{a776248f-c424-4ce4-8b5e-65db029465d3} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25151605-D156-49DD-A659-20E69C1EE15F} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{268CA04C-106C-4636-B707-95E8CD5859E0} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8C428C4B-C9E2-4B74-B791-88C3FEE48F36} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9F19923D-2A4C-45EF-A026-AE7DEE5D022C} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F67A3AA8-88EE-4A3A-863A-B13A19F8696C} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Found : HKLM\SOFTWARE\UtilityChest_49 Key Found : [x64] HKLM\SOFTWARE\AskPartnerNetwork Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{13B8FF9D-DEB0-4070-B846-D049218307B3} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1E877590-30B7-400E-A835-B942489EB7BC} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4} Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D} Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3} Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\90C64EA18BA25EE488BF80DCF07F2FFD Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon] Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater] Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [HomeworkSimplified_7e Browser Plugin Loader] Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [UtilityChest_49 Browser Plugin Loader 64] ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.17420 -\\ Mozilla Firefox v33.1 (x86 en-US) [jyvn16ad.default] - Line Found : user_pref("browser.search.defaultengine", "Ask.com"); [jyvn16ad.default] - Line Found : user_pref("browser.search.defaultenginename", "Ask.com"); [jyvn16ad.default] - Line Found : user_pref("browser.search.order.1", "Ask.com"); [jyvn16ad.default] - Line Found : user_pref("extensions.asktb.ff-original-keyword-url", ""); [jyvn16ad.default] - Line Found : user_pref("browser.startup.homepage", "hxxp://www.search.ask.com/?tpid=ORJ-ST-SPE&o=APN11463&pf=V7&trgb=FF&p2=%5EBE9%5EOSJ000%5EYY%5EUS&gct=hp&apn_ptnrs=BE9&apn_dtid=%5EOSJ000%5EYY%5EUS&apn_dbr=ff_30.[...] [k4ecvf1n.default] - Line Found : user_pref("CT3289663.1000082.isPlayDisplay", "true"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description\":\"California Rock - Rock\",\"url\":\"hxxp://www.feedlive.net/california.asx\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.1000234.TWC_TMP_city", "SAN JOSE"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.1000234.TWC_TMP_country", "US"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.1000234.TWC_country", "UNITED STATES"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.1000234.TWC_locId", "USCA0993"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.1000234.TWC_location", "San Jose, CA"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.1000234.TWC_region", "US"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.1000234.TWC_temp_dis", "f"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.1000234.TWC_wind_dis", "mph"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.FirstTime", "true"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.FirstTimeFF3", "true"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.RestartDialogFirstTime", "false"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.RestartDialogShouldDisplay", "false"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289663&octid=CT3289663&CUI=UN11478538711459430&UM=4&SearchSource=2&q="); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.UserID", "UN11478538711459430"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.addressBarTakeOverEnabledInHidden", "true"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.appOptions", "{\"1000515\":{\"render\":true}}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.browser.search.defaultthis.engineName", true); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.countryCode", "US"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.dum", "1"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.firstTimeDialogOpened", "true"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.fixPageNotFoundErrorByUser", "TRUE"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.fixPageNotFoundErrorInHidden", "true"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.fullUserID", "UN11478538711459430.IN.20130923225341"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.installType", "DirectDownload"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.isCheckedStartAsHidden", true); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.keyword", true); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?gd=&ctid=CT3289663&octid=CT3289663&ISID=ISID_ID&SearchSource=15&CUI=UN11478538711459430&Lay=1&[...] [k4ecvf1n.default] - Line Found : user_pref("CT3289663.lastVersion", "10.34.0.503"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.mam_gk_installer_preapproved.enc", "VFJVRQ=="); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.geekstogo.com%2Fforum%2Ftopic%2F345057-potentially-malicious-application-detected-dllhostexe%2F\",\"EB_MAIN_FRAM[...] [k4ecvf1n.default] - Line Found : user_pref("CT3289663.originalHomepage", "data:text/plain,browser.startup.homepage=hxxp://search.yahoo.com/firefox/?fr=sfp-yff17"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.originalSearchAddressUrl", "chrome://defaulttab/content/keywordURL.xul?"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.originalSearchEngine", "Ask.com"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.originalSearchEngineName", "Ask.com"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.performedDomainChangesMigration", "true"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.personalApps", "{\"dataType\":\"object\",\"data\":\"[\\\"BROWSER_COMPONENT\\\"]\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.revertSettingsEnabled", "false"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.search.searchAppId", "130067724014616498"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.search.searchCount", "0"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.searchFromAddressBarEnabledByUser", "true"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.searchInNewTabEnabledByUser", "true"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.searchInNewTabEnabledInHidden", "true"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.searchSuggestEnabledByUser", "TRUE"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.searchUninstallUserMode", "4"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.searchUserMode", "4"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3289663\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://InternetHelper31.OurToolbar.com//xpi\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"InternetHelper3.1 \"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_Configuration_lastUpdate", "1416145288508"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1401579430138"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_appsMetadata_lastUpdate", "1401579430366"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1401419937415"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_login_10.29.0.520_lastUpdate", "1399600046582"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_login_10.30.1.502_lastUpdate", "1401487425610"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_login_10.31.2.501_lastUpdate", "1404917627063"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_login_10.33.0.505_lastUpdate", "1410629176817"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_login_10.33.0.517_lastUpdate", "1413618757601"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_login_10.34.0.503_lastUpdate", "1416171888763"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1401419937389"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_searchAPI_lastUpdate", "1416145288193"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_serviceMap_lastUpdate", "1416145288072"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_setupAPI_lastUpdate", "1398511553670"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_toolbarContextMenu_lastUpdate", "1401579430145"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_toolbarSettings_lastUpdate", "1416171889955"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.serviceLayer_services_translation_lastUpdate", "1416145289958"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.settingsINI", true); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.showToolbarPermission", "false"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.smartbar.CTID", "CT3289663"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.smartbar.Uninstall", "0"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.smartbar.homepage", true); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.smartbar.toolbarName", "InternetHelper3.1 "); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.toolbarBornServerTime", "26-4-2014"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.toolbarCurrentServerTime", "17-11-2014"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.toolbarInstallDate", "25-04-2014 23:12:38"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663.toolbarLoginClientTime", "Sat Apr 26 2014 07:59:35 GMT-0400 (Eastern Standard Time)"); [k4ecvf1n.default] - Line Found : user_pref("CT3289663_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1416172364708,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]"); [k4ecvf1n.default] - Line Found : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "chrome://defaulttab/content/keywordURL.xul?"); [k4ecvf1n.default] - Line Found : user_pref("Smartbar.TBHomepagesList", "hxxp://search.conduit.com/?ctid=CT3289663&octid=CT3289663&CUI=UN11478538711459430&UM=4&SearchSource=13"); [k4ecvf1n.default] - Line Found : user_pref("Smartbar.TBSearchEngineList", ""); [k4ecvf1n.default] - Line Found : user_pref("Smartbar.TBSearchUrlList", ""); [k4ecvf1n.default] - Line Found : user_pref("Smartbar.keywordURLSelectedCTID", "CT3289663"); [k4ecvf1n.default] - Line Found : user_pref("browser.search.defaultengine", "Ask.com"); [k4ecvf1n.default] - Line Found : user_pref("browser.search.defaultenginename", "InternetHelper3.1 Customized Web Search"); [k4ecvf1n.default] - Line Found : user_pref("browser.search.order.2", "Ask.com"); [k4ecvf1n.default] - Line Found : user_pref("browser.search.selectedEngine", "InternetHelper3.1 Customized Web Search"); [k4ecvf1n.default] - Line Found : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3289663&octid=CT3289663&CUI=UN11478538711459430&UM=4&SearchSource=13"); [k4ecvf1n.default] - Line Found : user_pref("extensions.APN_TB.first-previous-keyword-url", "hxxp://trovi.com/ResultsExt.aspx?ctid=CT3289663&SearchSource=2&CUI=UN11478538711459430&UM=4&q="); [k4ecvf1n.default] - Line Found : user_pref("extensions.ORJ-ST-SPE.previous-keyword-url", "\"hxxp://trovi.com/ResultsExt.aspx?ctid=CT3289663&SearchSource=2&CUI=UN11478538711459430&UM=4&q=\""); [k4ecvf1n.default] - Line Found : user_pref("extensions.asktb.ff-original-keyword-url", ""); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.BUTTON_STRUCTURE", "[{\"b\":221352991,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":221352992,\"c\":\"mindspark.entersearchterms\",\"p\":\"L.0.0[...] [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.firstKnownVersion", "6.33.3.43582"); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=6B146627-5F72-4B5F-971C-5FA30902296B&n=780bd99b&p2=^ZO^xdm011^YYA^us&si=translateye"); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.initialized", true); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.installKeysSource", "File"); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.installation.contextKey", ""); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.installation.installDate", "2014042523"); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.installation.partnerId", "^ZO^xdm011^YYA^us"); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.installation.partnerSubId", "translateye"); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.installation.success", true); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.installation.toolbarId", "6B146627-5F72-4B5F-971C-5FA30902296B"); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.isCompliantUninstallImplementation", true); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.lastActivePing", "1416171880259"); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.lastKnownVersion", "6.72.4.54396"); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.options.defaultSearch", false); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.options.homePageEnabled", false); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.options.keywordEnabled", false); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.options.tabEnabled", false); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.successUrl", "hxxp://utilitychest.dl.tb.ask.com/installComplete.jhtml"); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.toolbarCollapsed", true); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark._49Members_.weather.location", "22554"); [k4ecvf1n.default] - Line Found : user_pref("extensions.toolbar.mindspark.lastInstalled", "utilitychest@mindspark.com"); [k4ecvf1n.default] - Line Found : user_pref("keyword.URL", "hxxp://trovi.com/ResultsExt.aspx?ctid=CT3289663&SearchSource=2&CUI=UN11478538711459430&UM=4&q="); [k4ecvf1n.default] - Line Found : user_pref("smartbar.addressBarOwnerCTID", "CT3289663"); [k4ecvf1n.default] - Line Found : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3289663&octid=CT3289663&CUI=UN11478538711459430&UM=4&SearchSource=13"); [k4ecvf1n.default] - Line Found : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289663&octid=CT3289663&CUI=UN11478538711459430&UM=4&SearchSource=2&q=,hxxp://trovi.com/ResultsExt.a[...] [k4ecvf1n.default] - Line Found : user_pref("smartbar.defaultSearchOwnerCTID", "CT3289663"); [k4ecvf1n.default] - Line Found : user_pref("smartbar.homePageOwnerCTID", "CT3289663"); [k4ecvf1n.default] - Line Found : user_pref("smartbar.homepageList", "hxxp://search.conduit.com/?ctid=CT3289663&octid=CT3289663&CUI=UN11478538711459430&UM=4&SearchSource=13"); [k4ecvf1n.default] - Line Found : user_pref("smartbar.machineId", "2QTAQOUN6VBRQ5+WQ92E7FB5UPYMHX8UWRRILJDZ5X+3EFX40QGG9Y51H5COZVARPLSUKBJXI6R5FIG4ESBVVA"); [k4ecvf1n.default] - Line Found : user_pref("smartbar.searchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289663&octid=CT3289663&CUI=UN11478538711459430&UM=4&SearchSource=2&q=,hxxp://trovi.com/ResultsExt.aspx?cti[...] [k4ecvf1n.default] - Line Found : user_pref("valueApps.CT3289663.mam_gk_currentVersion", "312E31332E302E3137"); [k4ecvf1n.default] - Line Found : user_pref("valueApps.CT3289663.mam_gk_currentVersion.storedInFile", false); [k4ecvf1n.default] - Line Found : user_pref("valueApps.CT3289663.mam_gk_migrated_from_ls", "31"); [k4ecvf1n.default] - Line Found : user_pref("valueApps.CT3289663.mam_gk_migrated_from_ls.storedInFile", false); [k4ecvf1n.default] - Line Found : user_pref("valueApps.CT3289663.mam_gk_userBornDate", "4E2F41"); [k4ecvf1n.default] - Line Found : user_pref("valueApps.CT3289663.mam_gk_userBornDate.storedInFile", false); [fd33t34s.default] - Line Found : user_pref("browser.search.defaultengine", "Ask.com"); [fd33t34s.default] - Line Found : user_pref("browser.search.order.1", "Ask.com"); [fd33t34s.default] - Line Found : user_pref("browser.startup.homepage", "hxxp://www.search.ask.com/?tpid=ORJ-ST-SPE&o=APN11463&pf=V7&trgb=FF&p2=%5EBE9%5EOSJ000%5EYY%5EUS&gct=hp&apn_ptnrs=BE9&apn_dtid=%5EOSJ000%5EYY%5EUS&apn_dbr=ff_30.[...] [fd33t34s.default] - Line Found : user_pref("extensions.asktb.ff-original-keyword-url", ""); [fd33t34s.default] - Line Found : user_pref("yahoo.ytff.toolbar.orignaldefaultenginename", "Ask.com"); [ao6m9a7j.default] - Line Found : user_pref("browser.search.defaultengine", "Ask.com"); [ao6m9a7j.default] - Line Found : user_pref("browser.search.defaultenginename", "Ask.com"); [ao6m9a7j.default] - Line Found : user_pref("browser.search.order.1", "Ask.com"); [ao6m9a7j.default] - Line Found : user_pref("extensions.asktb.ff-original-keyword-url", ""); [ao6m9a7j.default] - Line Found : user_pref("browser.startup.homepage", "hxxp://www.search.ask.com/?tpid=ORJ-ST-SPE&o=APN11463&pf=V7&trgb=FF&p2=%5EBE9%5EOSJ000%5EYY%5EUS&gct=hp&apn_ptnrs=BE9&apn_dtid=%5EOSJ000%5EYY%5EUS&apn_dbr=ff_30.[...] -\\ Google Chrome v38.0.2125.111 [C:\Users\Alyana\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.conduit.com/Results.aspx?ctid=CT3300019&SearchSource=45&UM=2&q={searchTerms} [C:\Users\Alyana\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.conduit.com/Results.aspx?ctid=CT3300019&SearchSource=45&UM=2&q={searchTerms} [C:\Users\Alyana\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms} [C:\Users\Alyana\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.ask.com/web?q={searchTerms} [C:\Users\Alyana\AppData\Local\Google\Chrome\User Data\Default\preferences] - Found [Extension] : aaaaojmikegpiepcfdkkjaplodkpfmlo [C:\Users\Billy\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://mysearch.sweetpacks.com?src=6&q={searchTerms}&barid=& [C:\Users\Billy\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=ORJ&o=&locale=&apn_uid=8461ACEF-8ED9-4E96-8369-450DDA46D4A0&apn_ptnrs=TV&apn_sauid=54DA90B7-F9CC-497D-872C-74DF2C1D0082&apn_dtid=OSJ000YYUS&q={searchTerms} [C:\Users\Billy\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=ORJ&o=&locale=&apn_uid=8461ACEF-8ED9-4E96-8369-450DDA46D4A0&apn_ptnrs=TV&apn_sauid=54DA90B7-F9CC-497D-872C-74DF2C1D0082&apn_dtid=OSJ000YYUS&q={searchTerms} [C:\Users\Billy\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN27383906343141190&ctid=CT3286042&UM=2 [C:\Users\Billy\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN27383906343141190&ctid=CT3286042&UM=2 [C:\Users\Billy\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms} [C:\Users\Billy\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.ask.com/web?q={searchTerms} [C:\Users\Billy\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://mysearch.sweetpacks.com?src=6&q={searchTerms}&barid=& [C:\Users\Kaliyah\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms} [C:\Users\Kaliyah\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.ask.com/web?q={searchTerms} [C:\Users\Kaliyah\AppData\Local\Google\Chrome\User Data\Default\preferences] - Found [Extension] : aaaaojmikegpiepcfdkkjaplodkpfmlo [C:\Users\Nyjah\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms} [C:\Users\Nyjah\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.ask.com/web?q={searchTerms} [C:\Users\Nyjah\AppData\Local\Google\Chrome\User Data\Default\preferences] - Found [Extension] : aaaaojmikegpiepcfdkkjaplodkpfmlo ************************* AdwCleaner[R0].txt - [46488 octets] - [16/11/2014 12:52:24] AdwCleaner[R1].txt - [45952 octets] - [16/11/2014 16:14:05] ########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [46013 octets] ##########